Executive brief
Vinyl Cache and Varnish Cache are high-performance web accelerators used to speed up websites by caching content. A security flaw in how these systems process modern web traffic (HTTP/2) could allow an attacker to 'smuggle' hidden requests to backend servers. This could lead to unauthorized access to data, the serving of incorrect or malicious content to other users (cache poisoning), or the bypassing of security controls.
Technical details
A vulnerability exists in the HTTP/2 request parsing logic of Vinyl Cache and Varnish Cache, classified as a Request Smuggling (CWE-444) flaw. By sending specially crafted HTTP/2 requests, an attacker can cause a desynchronization between the cache proxy and the backend server. This allows the attacker to 'smuggle' a second request inside the first, which the backend interprets as a separate, legitimate request. This can be leveraged for cache poisoning, bypassing authentication, or information disclosure. The vulnerability is only exploitable if HTTP/2 support is explicitly enabled (it is disabled by default). Patches are available in Vinyl Cache 9.0.1 and Varnish Cache 9.0.3, 8.0.2, and 6.0.18.
Affected products
- Vinyl Cache Project Vinyl Cache 9.0.0
- Varnish Software Varnish Cache 7.6.0 to 8.0.1, 6.0.14 to 6.0.17, and versions up to 9.0.2
Timeline
- 2026-05-18: disclosed: Initial publication of VSV00019 and release of patches.
- 2026-05-28: other: Advisory last updated.
- 2026-06-03: advisory: CVE-2026-50052 published to NVD.